Security & Privacy

Our customers trust us with highly sensitive information: the compensation of their employees. We take this responsibility seriously and built our products from the ground up with security and privacy in mind, including enterprise-grade protections, regular audits, and strong privacy standards.

Certified Secure

Pave meets leading security standards

ISO27001 Certified

Pave is ISO/IEC 27001:2022 certified, demonstrating our adherence to rigorous international standards for information security. This certification underscores our dedication to systematically managing sensitive information and ensuring data integrity.

SOC 2 Type 1 Compliance

Pave is SOC 2 Type 1 compliant. This attestation verifies we have effective controls in place for financial reporting, ensuring the accuracy and reliability of financial data processed through our platform.

SOC 2 Type 2 Compliance

Pave is SOC 2 Type 2 compliant. This attestation verifies our systems are designed to keep customer data secure, available, and confidential over time, reflecting the our commitment to ongoing operational excellence.

Client Controls

Take charge of your ecosystem with Pave

Pave enables best-in-class security for every client using the our platform. We offer Single-Sign-On (SSO) authentication, role-based access controls, and in-product data protection protocols to ensure you can confidently share sensitive compensation information based on the privileges you set for leaders, people managers, and employees.

Private by Design

Pave integrates privacy into every process

GDPR & CCPA

Pave adheres to the California Consumer Privacy Act (CCPA) and the European Union’s General Data Protection Regulation (GDPR), ensuring data is processed lawfully, transparently, and securely. We work closely with clients to meet their compliance requirements under these regulations.

Aggregated & De-Identified Data

Pave does NOT use personally identifiable information (PII) in our Market Data products. These products only use aggregated and de-identified data.

Enterprise-Grade Data Storage

Pave stores data in the United States, utilizing enterprise-grade cloud storage provided by Google Data Centers. We follow data storage best practices that comply with relevant regulations and industry standards.

Data Access

Pave enforces the principle of “Least Privilege,” ensuring employees only have access to the data necessary for their roles. This approach minimizes the risk of unauthorized data exposure and maintains strict confidentiality.

Data Transfers

Pave uses the most up to date Standard Contractual Clauses for transfers between customers and Pave, and between Pave and our subprocessors.

Added Protections

Going the extra mile to protect clients

Beyond the security and privacy protections listed above, Pave goes even further to protect clients. We have a dedicated security team, we conduct bi-annual penetration testing through third-party providers, we encrypt data at rest and in transit, and we run a paid bug bounty program.

Maximize the impact of every pay decision with Pave